5
CVSSv2

CVE-2006-2481

Published: 31/07/2006 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

VMware ESX Server 2.0.x prior to 2.0.2 and 2.x prior to 2.5.2 patch 4 stores authentication credentials in base 64 encoded format in the vmware.mui.kid and vmware.mui.sid cookies, which allows malicious users to gain privileges by obtaining the cookies using attacks such as cross-site scripting (CVE-2005-3619).

Vulnerable Product Search on Vulmon Subscribe to Product

vmware esx 2.1

vmware esx 2.1.1

vmware esx 2.0

vmware esx 2.0.1

vmware esx 2.5.2

vmware esx 2.1.2

vmware esx 2.5

Exploits

source: wwwsecurityfocuscom/bid/19249/info VMware ESX is prone to multiple information-disclosure vulnerabilities These issues are due to a design error in the application The following issues were reported: 1 An information disclosure vulnerability that could disclose the session ID, username, and password if an attacker can access s ...